Framework National Cyber & Cloud Schemes
ISMAP
ISMAP (Information system Security Management and Assessment Program) is the Japanese government's scheme for evaluating and registering cloud services that meet its security requirements so that ministries and agencies can procure them without repeating the assessment.
It was announced in May 2020 and is run jointly by the National center of Incident readiness and Strategy for Cybersecurity (NISC), the Digital Agency, the Ministry of Internal Affairs and Communications, and the Ministry of Economy, Trade and Industry, with the Information-technology Promotion Agency (IPA) operating the program.
The control set (the ISMAP management standards) is built on JIS Q 27001, 27002, and 27017 with government-specific additions. A cloud provider implements the controls, has them examined by an audit firm registered on the ISMAP assessor list, and applies for registration; the ISMAP Steering Committee reviews the application and lists the service in the ISMAP Cloud Service List.
ISMAP-LIU (for Low-Impact Use), introduced in 2022, is a lighter track for SaaS used in low-risk government work.
In writing, a provider needs a management system aligned to the ISMAP standards, a control matrix with implementation statements for every applicable control, the system description and service scope, evidence of operating effectiveness for the audit period, the registered assessor's report, and the application package. Registration is renewed annually with a fresh assessment.
help
Who has to comply
Cloud service providers, Japanese or foreign, that want to sell to Japanese central government bodies, which are required to procure registered services in principle. Local governments and regulated industries increasingly reference the list as well.
What the assessor asks to see
Service scope and system description; ISMAP management standards control matrix with implementation statements; information security policy set; risk assessment; access management, cryptography, logging, change and vulnerability management, and incident handling evidence for the audit period; subcontractor and supply chain controls; data location information; business continuity tests; internal audit and management review; the registered assessor's report; prior registration records.
ISMAP-LIU
ISMAP for Low-Impact Use, launched in 2022, is a streamlined track for SaaS handling government information of lower sensitivity, with a narrower control set and lighter documentation while keeping an independent assessment and annual renewal.
Assessors
Who assesses ISMAP
Audit firms registered on the ISMAP assessor list maintained by IPA (in practice the large Japanese audit firms and affiliates of international networks). Registration decisions are made by the ISMAP Steering Committee. Accredited by IPA (as ISMAP operator) registers assessors; assessors are typically CPA-regulated audit firms operating under Japanese assurance standards.
Public register of assessors: https://www.ismap.go.jp/csm
No firm has claimed a ISMAP assessor listing yet. Claim yours →
Consultants
Who helps with ISMAP
Japanese consultancies and the advisory arms of audit firms help providers map controls, translate documentation, and prepare for the assessment; global providers often use a Japan-based partner. Readiness typically takes six to twelve months.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a ISMAP consultant listing yet. Claim yours →
Software
Tools for ISMAP
Tools that name this framework in their own material.
No firm has claimed a ISMAP tool listing yet. Claim yours →
Related reading
- Information System Security Management and Assessment Program (ISMAP)Assessor's view of the registration path, the approved-assessor requirement and the improvement plan expected after findings.EY Japan
- ISMAP complianceDescribes what registration means for a cloud service and how Japanese government buyers use the ISMAP cloud service list.Amazon Web Services
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for ISMAP
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with ISMAP
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.